The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3.0 allows remote attackers to execute arbitrary code via crafted input to the (1) GetSymmCmdRequest or (2) RemoteServiceHandler class.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDell Emc Unisphere
APPDell8.08.18.1.28.2Emc Solutions Enabler
APPEmc8.08.0.38.18.1.28.3Emc Unisphere
APPEmc8.0.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
Related vulnerabilities
CVE-2018-1183CRITICAL9.8PL ✓same product
XXE Injection w komponentach ECOM systemów Dell EMC (RCE/ujawnienie danych)
CVE-2017-14375CRITICAL9.8PL ✓same product
Pominięcie uwierzytelnienia w EMC Unisphere, Solutions Enabler, VASA i VMAX eManagement
CVE-2016-0889CRITICAL9.8PL ✓same product
Zapis do dowolnych plików w EMC Unisphere for VMAX Virtual Appliance
CVE-2016-6645HIGH8.8same product
The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions E...
CVE-2015-0545HIGH10.0same product
EMC Unisphere for VMAX 8.x before 8.0.3.4 sets up the Java Debugging Wire Protocol (JDWP) service, which allow...